PT-2010-2437 · Digium · Asterisk Business Edition+1
Published
2010-02-23
·
Updated
2018-10-10
·
CVE-2010-0685
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Asterisk Open Source versions 1.2.x through 1.6.x
Asterisk Business Edition versions B.x.x through C.x.x
Description
The dialplan functionality in Asterisk allows context-dependent attackers to inject strings into the dialplan using metacharacters that are injected when the ${EXTEN} channel variable is expanded. This can be demonstrated using the Dial application to process a crafted SIP INVITE message, potentially adding an unintended outgoing channel leg.
Recommendations
For Asterisk Open Source versions 1.2.x through 1.6.x, consider implementing filtering functionality to prevent metacharacter injection when using the ${EXTEN} channel variable.
For Asterisk Business Edition versions B.x.x through C.x.x, consider implementing filtering functionality to prevent metacharacter injection when using the ${EXTEN} channel variable.
As a temporary workaround, consider restricting the use of the Dial application with crafted SIP INVITE messages until a more comprehensive solution is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asterisk Business Edition
Asterisk Open Source